1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

has someone hacked my sites cookies? (myspace cookie on my site)

Discussion in 'BlackHat Lounge' started by JimAMG, Sep 9, 2014.

  1. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    i've been having a weird thing happen lately ... when i arrive at my homepage or another page on my site, sometimes (not always) i get a piece of music playing for a few seconds (its deffo my site cos i've closed the tab while it was playing and it stops) ... but when my wife visits the site (using a different computer and broadband connection) she gets a different piece of music and sometimes some talking with a lot of background noise.

    thing is, i always get the music i get, and she always gets the music she gets, but they are different from each other which got me thing about the cookies... so i took a look at cookie-checker and i see 6 third party cookies...

    the two cookies i suspect to be behind this look like they have come from b12.myspace - theres no reason for them to be there, and from what i remember from when i checked before while researching the eu cookie law, they werent on my site when i looked previously

    has anyone else had music appearing on their site, or got any thoughts ... am i on the right track with what might be behind the sounds?

    it's been happening for a couple of weeks and business has been tough enough lately without weird sounds putting customers off!

    cheers all

    Jim
     
  2. spacetraveler

    spacetraveler Newbie

    Joined:
    Sep 9, 2014
    Messages:
    3
    Likes Received:
    0
    Are you running third-party ads on your site?
     
  3. bookmarc

    bookmarc Senior Member

    Joined:
    Jul 11, 2009
    Messages:
    1,052
    Likes Received:
    480
    see the source of your page.
    look for iframes
    or look for codes you did'nt put or dont recognize. and search for it.
    or use software like wireshark to see what info you site is sending or receiving.
     
  4. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    no, i'm not, i have statcounter and sitemeter and there's a sitemeter cookie too but AFAICS there is no reason for my site to be loading a myspace cookie, let along 2 of them - both persistent

    theres also one from vindicosuite which i dont know anything about ... presume statcounter will have one but theres nothing named 'statcounter'
     
  5. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    would an iframe show up if i just look at the source of my page via my browser (tools>view source)? nothing there AFAICS
     
  6. JavaBots

    JavaBots Newbie

    Joined:
    Jul 20, 2014
    Messages:
    2
    Likes Received:
    1
    can you pm your site i can check it out you might have hidden javascript code or hidden embed element
     
  7. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    cheers, i can't pm as i have less than 15 posts, and can't post the actual url or anything near it, because of the auto modding system but it's 4x4cb and it's a 3 letter tld, the main non country-specific one, lol
     
  8. JavaBots

    JavaBots Newbie

    Joined:
    Jul 20, 2014
    Messages:
    2
    Likes Received:
    1
    49bcf7f72577f57678ed3351e6a7367a.jpg
    does that look correct site?
     
  9. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    yeah, thats the one, i retail cb radios for a living!
     
  10. JavaBots

    JavaBots Newbie

    Joined:
    Jul 20, 2014
    Messages:
    2
    Likes Received:
    1
    Looks like your site is offline for now, returning 500 error by TomCat Apache
     
  11. DatMoney

    DatMoney Regular Member

    Joined:
    Jul 20, 2014
    Messages:
    238
    Likes Received:
    103
    Occupation:
    Chief Engineer at NASA
    Location:
    New York, United Kingdom
    Home Page:
    I just checked your site using Fiddler. The only cookie I got was of statcounter. Seems like a problem with your and your wife's PC. Nothing wrong with site
     
  12. JavaBots

    JavaBots Newbie

    Joined:
    Jul 20, 2014
    Messages:
    2
    Likes Received:
    1
    You're wrong please get better tools


    i've got results:
    979f2fd6801feb4cad288b9d701e40c2.png
    the url above is linking to myspace
     
    • Thanks Thanks x 1
  13. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    javabots, it sometimes drops as the site is very old and runs in coldfusion and has an ms access database which the latest version of coldfusion hates, throws errors now and again, try again and it should be up.

    datmoney, both mine and the mrs's computers are fairly new machines, bought from different places, in different locations and different connections. we have very different surfing habits, so apart from stuff like gmail, ebay, amazon etc we share no sites that we visit, and we dont exchange files or share a usb key or anything like that so the probability of us both having picked up something thats causing this is small - not impossible, but it would seem unlikely
     
  14. JavaBots

    JavaBots Newbie

    Joined:
    Jul 20, 2014
    Messages:
    2
    Likes Received:
    1
    Okay but did you check above post i found the hidden iframe which is linking to myspace
     
  15. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    i think you may've hit on it, pretty sure specific click is something to do with sitemeter and i do have one of their counters on there, plus on a few other pages too, think i might have to remove that and clear my cookies and see if it stops the sounds appearing ... i'm only assuming it's the myspace cookie thats the problem, as it's mainly music and theres a lot of music on myspace!
     
  16. JimAMG

    JimAMG Newbie

    Joined:
    Nov 20, 2013
    Messages:
    1
    Likes Received:
    1
    Occupation:
    Dayjob running an online business selling radio eq
    Location:
    Dorking, Surrey, UK
    Home Page:
    Javabots, you're a star, i've just been on sitemeter and while on their homepage, a video window appeared and started playing some content from myspace and it had a faltering start like the sounds on my site sometimes do (i live in the middle of the woods, far from the exchange and my internet speed is very poor), so i'm pretty sure sitemeter is responsible for the problem ... quite what the hell they are doing trying to make the player open up when visitors hit my site i dont know, but seems thats what it is!

    now to remove every meter, had some on product pages and all over the place at one point, so this'll be fun!

    Thanks again mate

    Jim